Reduction
The OywePAp recommends some reduction above those discussed above, including a strong environmental environment, using a few control over the environment, as well as infrastructure to separate sensitive resources. Also, the theme here promotes formal impacts and restricting them in these reductions and steps.
Health of NHI No 9: To reuse NHIis
The Credential reuse long caused him to warn it and yet it has been a personal way, the best guidelines, and more. That is why it is unlikely to see it’s listed here as a dangerous NHIS hazard.
Orvisep
As the table above speaks, the granur permits of the granur of each NHI can be complex, so that organizations may work through the energy of the NHIs. This makes them compulsory stones explicit about the extent of impact on the postponement.
The Owspasp discusses NHIis accounts, such as the service accounts, API keys, and the authenticity of the equipment, is important for modern applications, services, and approval.
Suppose organizations re-use nts in all applications and services. In that case, the chances of developing an important impact – may result in vulnerability / attack against the organization’s organization if one of the recycled NTIs, especially if they have a large number of (NHI5). There is a lack of environment that separates (NHI8).
The OwASP provides examples such as recycling for the Bernetes service accounts, sharing the API buttons between applications, and recycling cloud guarantees such as AWS services and resources.
Reduction
Reduce these risks, Oaspp recommending the unique NHIis in each application or the environment, enforcing the purpose of obtaining a small right, monitoring and reviewing the use of the NHIis.
NHI NHI 10: Personal use of NHI
NHIis, such as service accounts, API tokens, ownership of employee responsibility, confidentiality, enabling proamtales access to applications and services. That means, as an ยท char is discussing, it is not uncommon for developers or users to misuse the NHIs on booking work instead of the original purpose of the automated jobs and work.

Orvisep
Lokhu kubeka engcupheni eminingana ngoba imisebenzi yabantu ingabonakala njengohlelo, ukuxhashazwa nokuhlola, ukumboza imisebenzi ngokungenisa ngaphakathi, noma izinsongo ezingagxili kakhulu, futhi, ikakhulukazi, ikakhulukazi, kunakho, futhi, ikakhulukazi, ikakhulukazi, kunakho, futhi, ikakhulukazi, ikakhulukazi, kunakho, futhi, ikakhulukazi , more, too, especially, right, again, especially, right, and, especially, most of the attackers.
Owasp Cities Example Symptomatic Example Using Service Account Account Guarantees, Developers
Reduction
The last set of lesser risks in the Essst NHI higher 10 includes using a dedicated ownership, audit and monitoring a number of information (using several times), as well as educating developers and risk management. These measures provide technical and cultural controls to reduce human use of the NHIS and their associated risk.
Source link